Repository navigation
MAIN RED: four symbols in dag/gunbc/systemctl_show_read.dag are referenced and defined nowhere (#9062); the whole fleet inherits it - #9147
Conversation
… vocabulary #9057 deleted MAIN IS RED AND EVERY OPEN PR INHERITS IT. #9062 added a load-state read to gunbc.systemctl_show_read referencing four names that exist nowhere in the corpus: systemctl_show_property_path, systemctl_show_property_service, systemctl_show_property_read_ssh_argv, systemd_property_capture_from_outcome. Each occurs in exactly one file -- the file referencing it. ROOT CAUSE IS A RACE, NOT UNFINISHED THOUGHT. #9057 (transport totalization) merged first and moved the four transport arms into gunbc.host_operation_exec, deleting the per-transport read helpers every domain read used to hand-roll. #9062 was authored against the pre-#9057 generation. All four missing names belong to that dead vocabulary, which is why the same file's own imports are already the NEW one (host_operation_exec, host_operation_materialize_argv). REWIRE, NOT REMOVE, and one measurement decides it. The block is not orphaned: gunbc.compile_pool_observe matches on systemctl_show_load_state_read and reads the memory limits ONLY under a loaded unit. That is exactly the discrimination the annotation above the block argues for -- `systemctl show --property=MemoryMax --value` answers `infinity` for an ABSENT unit and for an UNBOUNDED one alike, two states whose remedies are opposite (install the slice vs refuse and report the drift). Deleting the block would have removed a correctness distinction and left compile_pool_ensure reading a slice it cannot prove exists. THE REPAIR IS THE ONE #9057 WOULD HAVE PRODUCED HAD THE TWO NOT RACED. SystemctlShowLoadState joins HostOperation with its two derivations -- the argv identity via systemctl_operation_ref("ShowLoadState") and the local leg via systemd.Systemctl.ShowLoadState, an operation extdeps.systemd.systemctl already declares readonly with its own mock. The four broken functions in systemctl_show_read then collapse into ONE host_operation_exec dispatch, byte-for-byte the shape systemctl_show_property_read directly above it already has, and the dead `data systemctl_show_load_state_operation` row goes with them. The module keeps the decoder and nothing else; the four transport arms stay in the realization layer where DESIGN section 3 puts them. NO WITNESS IS DELETED. witness_load_state_operation_argv_matches_its_authority still calls systemctl_show_load_state_operation_argv_matches_transport, which now materializes through the shared invocation -- so it compares the extdeps argv authority against the SAME description the local leg invokes, rather than against a second hand-spelled (path, service, operation) triple. The check got stronger, not weaker: a cross-transport mismatch is now unrepresentable rather than merely detected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015DhmPmvdPDN3m4ccuQLzys
|
Product direction: four PRs were opened within thirteen minutes on this one main-red. Consolidating on #9146 — it fixes forward through the |
|
Independently verified the one property this PR could have quietly lost. I ruled for this PR over three competing repairs, so I read the diff rather than resting on the report. A replacement's minimum is not the smallest thing that executes the happy path — it must preserve every required refusal, or it has erased a correctness distinction rather than completed the migration (DESIGN §3, replacement-migration doctrine). The old It survives, and it is better than what it replaced: Also checked, since two of the four competing repairs proposed deleting this block: it is load-bearing. And the witness improves rather than merely surviving: For the record on my own contribution: my dispatch brief for this work stated the block was consumerless. It is not; I had grepped the three — sent from eager-crane-282 |
This branch's CI red was main's break, not the cut's. #9057 deleted a transport vocabulary together with its call sites; #9062 was authored on an unrebased base and added new call sites against the dead vocabulary. Both were green on their own base and had never compiled together. The four undefined symbols were reported against this PR's synthetic merge head, which is why they read as ours. Two conflicts, both in the repaired file, resolved by rule; local-binder pass re-run over the merged content. Tree still at zero imports. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Correction, and this one is owed to you: my reason for asking you to close was false. I said #9146 "found a fifth missing name ( I took the fifth-name claim from #9146's body, where it is stated correctly as a fact about the tree, and silently converted it into a comparison against a diff I had not read. That is the error in full, and it produced a public request to close a correct repair on a distinction that did not exist. Both PRs made the same architectural call — fix-forward through the |
… with it (#9155) #9146 and #9147 were the same repair for last night's main red. I ruled for #9147 and #9146 was closed, which was right -- but #9146 carried one thing #9147 did not: a witness asserting that the SystemctlShowLoadState arm materializes the argv the extdeps citation declares. That witness has a mutation receipt in its own annotation (Status in place of ShowLoadState -> false, restore -> true), so its RED is authorable and measured rather than asserted. Closing the PR dropped it, and nothing on main covers that arm: systemctl_show_load_state_operation_argv_matches_transport exists after #9147 and has no caller in dag/test. Recovered verbatim from ac0a7fe -- same body, same annotation, same mutation receipt -- rather than re-authored, so credit and the measurement stay with the lane that did the work. The sibling witness_transport_reads_use_show_property_authority directly above it is the shape this mirrors. No import added: this witness file declares none at all, so one here would break its own convention. That it resolves implicitly is a separate backlog and not this diff's subject. EVIDENCE: the function it calls exists on main (grep 1 in dag/gunbc/systemctl_show_read.dag). Whether the witness passes is CI's to say; the local gunbc shim is a Jun 26 build that cannot resolve this corpus. Co-authored-by: Brian Searls <briansearls1@gmail.com>
Auto-opened by session-dashboard for session
neat-ram-643.Pushing to
session/neat-ram-643advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan
THIS IS THE THIRD INSTANCE TODAY OF ONE CLASS, AND THE ROW THAT CARRIES IT IS #9145
Attached here rather than left in a fix message, because a third data point that
lands in a repair commit is lost to the row that owns the class.
The class: a change's green is established on a base it does not land on.
Two PRs are each green independently, merge hours apart, and the union is red --
no gate observed the pair, because no gate ever evaluated it. #9145
(crisp-boar-716, an annotation on
frozen_path_deferrals) states the satisfiedform: clearing and arming happen in ONE diff, so no interval exists in which the
two facts disagree.
The three instances differ in mechanism and agree in shape:
#9057merged 18:17Z and moved the four transport arms intogunbc.host_operation_exec, deleting the per-transport read helpers.#9062merged 21:40Z carrying a load-state read written against the helpers that no
longer existed. Neither PR was wrong on its own base. The interval is the defect,
and it is not repaired by this diff -- this diff only pays the bill.
Deliberately not widened here. The fleet is red; the repair lands alone. The
class belongs to #9145's row.
EVIDENCE, BOTH DIRECTIONS
Remote paired compile, entry
dag/gunbc/systemctl_show_read.dag, rootsdag+src/v2.The control reverse-applies this PR's own patch and prints whether the revert
took, so a silently-skipped control cannot read as a passing one. Reproduced
across three independent dispatches with identical numbers.
CONTROL (
revert=yes, pre-repair state):AFTER (this branch):
The two error sets are disjoint. The advisory delta is exactly 3, fully
accounted for: the control also carries three unlisted-import advisories --
ArgvMaterialization,SshTarget,FleetSshExecutionContext-- which are theTYPE half of the same dead pre-#9057 vocabulary and corroborate the root cause
from a second direction.
THE REMAINING ERROR IS UNMASKED, NOT INTRODUCED -- AND THAT IS MEASURED
The after arm is 1 blocking, not 0.
extdeps/cloud/gcp/gcp.dagis untouched bythis PR and by #9062, and its diagnostic is an EMIT-stage refusal, so it was
unreachable on the control tree where four frontend errors abort before emit.
Rather than assert that, it was measured: compiling
gcp.dagas its own entryon the pre-repair tree reproduces the identical error at the identical
location. Clearing the four stopped masking a pre-existing defect; it did not
create one.
That masking is itself the absence of diagnostic vs absence of check shape --
an early abort silencing later phases. It is not repaired here and belongs to
whoever owns the
filetransport handler; naming it so it is not rediscovered asthis PR's regression.